DIAGNOSTIC PLAYBOOK
TLS-RPT certificate failures and policy failures need different fixes
TLS reports distinguish failure categories that can arise at different parts of delivery. A certificate problem, policy-fetch problem and MX mismatch should not be grouped into one generic encryption outage.
HealthCheck Email editorial team · · Examples are illustrative
How to investigate
- Read the reported policy type and failure category for the affected destination.
- Match the category with a direct test of the relevant HTTPS or SMTP endpoint.
- Assign the issue to the team controlling that endpoint and verify the exact failure condition after repair.
What this looks like
ILLUSTRATIVE EXAMPLE
A report contains a policy retrieval error and a separate expired SMTP certificate. Renewing the web certificate cannot resolve the SMTP server's expiration.
A mistake to avoid
Reports summarize observations from particular senders. Use time and destination context when comparing them with current live checks.
Keep the result in context
Transport encryption protects a connection between mail systems. It is different from message authentication and does not imply end-to-end encryption. Investigate the receiving MX hostname, the TLS session and the applicable policy separately before deciding which system needs a change.
Take the next step
Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.
Sources and further reading
The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.